Broadcom has been using Mythos (Project Glasswing) to find and address security vulnerabilities since the beginning. Here are recent comments about that from Explore 2026.
We hear a lot about Mythos. I mean, everyone’s talking about it because it’s so powerful as identifying vulnerabilities everywhere. What’s been your experience, and how do the VMware customers, Broadcom customers leverage that? What’s the update there? And you mentioned you’re investing billions of tokens. What, how does Mythos play into this, and how does that impact the customer?
John Furrier on theCUBE, Aug 31, 2026
Purnima Padmanabhan, VP and GM, Tanzu Division
Look, we have had Mythos since the beginning – original Glasswing launch, if you may. And there are two ways we use Mythos. One is we are leveraging Mythos to scan our own commercial repositories. And really, it’s not just blindly scanning. There’s a lot of skills that we have built around it: how to red team and how to blue team against the software. And we are finding issues and we are patching it. We are aggressively patching our commercial software so that our customers are secure, and we’re proactively doing that. But we are also doing the same thing for open source, and that many people may not know.
Purnima Padmanabhan, VP and GM, Tanzu Division on theCUBE, Aug 31, 2026
And:
We are really focused on Spring and the Java ecosystem below Spring, and we have been scanning all of that with Mythos. Now let me be clear, if there was any doubt: we are finding issues, we are finding vulnerabilities, and these vulnerabilities are not just your low-level vulnerabilities. These are things that can completely bring down an enterprise. And so we take that job very seriously, and we’ve been investing billions in scanning that software.
Purnima Padmanabhan, VP and GM, Tanzu Division on theCUBE, Aug 31, 2026
…Broadcom is investing heavily, and when I talk about billions of Mythos tokens, right, to make sure that we scan and secure open source for the enterprise. We have a very strong open-source discipline with our enterprise Spring capabilities. We are the primary, sole committers.
Purnima Padmanabhan, VP and GM, Tanzu Division on theCUBE, Aug 31, 2026
More:
Broadcom engineers continuously scan Spring and its dependency tree with frontier model analysis, then verify every patch by hand, finding vulnerabilities before attackers do. In the past five months, engineers have already spent more than 12 billion tokens against frontier models.
“Broadcom Strengthens Spring Security and Adds Coverage of Java, Python, and Node.js Ecosystems with TrueSource,” 2026-08-31
Krish Prasad, SVP and GM, VMware Cloud Foundation
As you well know, we were one of the few select companies that was part of Glasswing. So we got early access to the Mythos models, and so we were able to run it on our own software and got a head start in actually making our software more hardened. So that’s number one. So we really have built Mythos, like frontier models, into our software development life cycle. So our infrastructure is pre-hardened by the time customers get it. Number two is that the customers are expecting us, as we find problems in the software vulnerabilities, to fix it on an ongoing basis. So we have made a commitment to customers that we will do ongoing patching of the environment, because these models are very powerful.
Krish Prasad, SVP and GM, VMware Cloud Foundation on theCUBE, Aug 31, 2026
Umesh Mahajan, VP and GM, Application Networking and Security Division
Mahajan: And then with our IDS/IPS we have a lot of signatures available. We have a signature pipeline which we are enhancing with agentic AI. Of course you use AI to further advance –
John Furrier: Mythos could be a double-edged sword. One hand is good and other hand’s bad.
Mahajan: But we have to use it. We have to use it to make our security better, right? Otherwise, we won’t be able to fight.
Umesh Mahajan and John Furrier on theCUBE, Aug 31, 2026
Leave a Reply